Privacy Policy

SafeME™ · operated by Cay Sal Holdings LLC, a Delaware limited liability company

Effective date: August 5, 2026

This Privacy Policy ("Policy") describes the manner in which SafeME, a platform operated by Cay Sal Holdings LLC ("SafeME," "Company," "we," "us," or "our"), collects, uses, maintains, retains, and safeguards information relating to individuals who access or utilize the SafeME website, application, marketplace, and related services (collectively, the "Services").

By accessing, registering for, or otherwise using the Services, you acknowledge that you have read, understood, and agreed to the practices described in this Policy.

1. Scope and Applicability

This Policy applies to all individuals whose information is processed in connection with the Services, including independent professionals seeking opportunities through the platform, representatives and account holders of businesses utilizing the platform to engage professionals, and authorized users affiliated with provider organizations participating in the Services. This Policy governs information collected directly from users, generated through use of the Services, or obtained in connection with the operation, administration, and security of the marketplace.

2. Categories of Information Collected

In the ordinary course of operating the Services, the Company collects information reasonably necessary to facilitate marketplace transactions, verify eligibility, administer engagements, process payments, maintain auditability, and comply with contractual and legal obligations.

With respect to professionals, the Company may collect personal and professional information including name, electronic mail address, telephone number, residential ZIP code, professional background and experience information, credential and certification records, images or photographs of supporting credential documentation, optional Errors and Omissions insurance documentation, and ratings or evaluations generated through platform activity.

With respect to business users, the Company may collect company identification and contact information, including business name, mailing address, ZIP code, telephone number, electronic mail address, industry classification, business size information, and the identity and contact information of the designated account holder.

With respect to provider organizations, the Company may collect the organization's identifying information, together with the names and email addresses of authorized users. Where expressly authorized by the applicable user, the Company may also maintain records reflecting work type and dates of service activity for purposes contemplated by the Terms and Services and other agreements.

The Company may additionally generate and maintain operational records arising from the use of the Services, including engagement histories, offers, transaction records, payment amounts, payment references supplied by Stripe, dispute records, audit logs, event histories, and records documenting user consents and modifications thereto.

For the avoidance of doubt, the Company does not intentionally collect health information, biometric information, or government-issued identification numbers. Where identity verification services are required, such services are conducted through Stripe or its designated verification providers. The Company does not receive or retain users' payment card numbers or bank account numbers.

3. Credential Verification

The Services require the verification of certain professional credentials as a condition of eligibility for participation in specific marketplace opportunities. In connection with such verification activities, the Company may collect and store credential records and supporting documentation submitted by professionals.

Verification is conducted through human review utilizing information obtained from the applicable issuing authority. The Company may disclose credential identifiers and related verification information to credentialing bodies, certification boards, licensing authorities, or similar organizations for the sole purpose of confirming authenticity, status, and eligibility.

Credential documentation is retained exclusively for marketplace administration, compliance, dispute resolution, and audit purposes and is not used for advertising, behavioral profiling, or unrelated commercial activities.

4. Purposes of Processing

The Company processes information solely for legitimate business purposes associated with the operation of the Services. Such purposes include establishing and maintaining user accounts, verifying identities and professional qualifications, determining eligibility for marketplace participation, facilitating geographic and qualification-based matching, managing engagements between users, administering escrow and payment functions, addressing disputes, enforcing contractual obligations, responding to user inquiries, monitoring compliance with platform requirements, maintaining audit trails, protecting the security and integrity of the Services, and communicating operational notices concerning platform functionality.

The Company does not sell personal information, license personal information for independent commercial use by third parties, or utilize user information for third-party advertising or marketing campaigns.

Communications distributed through the Services are limited to transactional, operational, security-related, administrative, or platform-wide announcement purposes, including approved waitlist communications.

5. Automated Processes

The Company does not employ artificial intelligence profiling, predictive behavioral scoring, automated employment decision-making, or other forms of algorithmic profiling intended to evaluate an individual's performance, character, reputation, or suitability.

The Services currently utilize only limited rules-based automations. First, access to certain opportunities may be restricted based upon the existence, expiration status, or verification status of applicable credentials. Second, escrowed funds may be released automatically upon expiration of predetermined contractual periods established within the Services. Notwithstanding the foregoing, credential approval and verification determinations are performed through human review utilizing information obtained from the applicable credential issuer.

6. Disclosure of Information

The Company discloses information only where necessary to operate the Services, fulfill contractual obligations, comply with law, or protect legitimate business interests.

Information may be disclosed to Stripe and its affiliates for payment processing, escrow administration, payout facilitation, fraud prevention, identity verification, regulatory compliance, and related financial services. Information may also be disclosed to credentialing organizations when required to verify submitted credentials.

Subject to the applicable Terms of Service and any required user authorization, information may be disclosed to participating provider organizations. Additionally, limited profile information may be made available to prospective engagement participants in anonymized form during initial matching and opportunity evaluation stages. Personally identifying information, including names and direct contact information, is generally disclosed only after a hiring decision, engagement acceptance, or equivalent relationship has been established through the platform.

The Company further utilizes third-party infrastructure and technology providers, including hosting, networking, security, and content delivery providers such as Netlify and Cloudflare. Such entities process information solely on behalf of the Company and subject to contractual confidentiality and security obligations.

The Company reserves the right to disclose information where reasonably necessary to comply with applicable law, legal process, regulatory inquiry, governmental request, contractual enforcement requirements, fraud prevention initiatives, security investigations, or the protection of the rights, property, or safety of the Company, its users, or the public.

7. Data Storage and International Transfers

The Services are intended exclusively for use within the United States. User information is intended to be stored within the United States, although data transmissions may transit through geographically distributed networks and content delivery infrastructure as part of ordinary internet communications and technical operations. Such transfers shall be limited to those reasonably necessary for the provision, security, and performance of the Services.

8. Data Retention

The Company retains information only for so long as reasonably necessary to fulfill the purposes for which it was collected, comply with legal and contractual obligations, resolve disputes, maintain business records, conduct audits, enforce agreements, and protect the integrity of the Services.

Temporary files may be retained for approximately ninety (90) days, while operational records may be retained for a minimum of one hundred eighty (180) days and for longer periods where required by law, legitimate business necessity, dispute resolution requirements, fraud prevention obligations, accounting standards, or enforcement considerations. Upon expiration of the applicable retention period, information shall be deleted, anonymized, archived, or otherwise disposed of using commercially reasonable safeguards.

9. Security Measures

Credit Cards and identity documents are never on the SafeME infrastructure — Stripe stores this data when collected from the professionals.

The Company maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, acquisition, disclosure, alteration, or destruction. Such safeguards include password-protected accounts, multifactor authentication for administrative users, password re-authentication for designated consequential actions, role-based access controls, session revocation capabilities, append-only audit logging, encrypted network communications utilizing industry-standard transport security protocols, and dual-approval requirements for fund movements where applicable.

While the Company endeavors to employ reasonable security measures, no system, network, or transmission method can be guaranteed to be completely secure. Users remain responsible for safeguarding their account credentials and promptly reporting suspected unauthorized activity.

10. Individual Rights and Choices

Users may review, access, and modify certain account information through the settings and profile functionality made available within the Services.

Where processing is based upon user consent, consent may be withdrawn at any time through available self-service account settings. Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to the withdrawal becoming effective.

Users may request deletion of personal information by submitting a written request to support@safemeapp.com. The Company may deny or limit deletion requests to the extent retention is required by applicable law, contractual obligation, dispute resolution requirements, fraud prevention needs, audit requirements, or legitimate business purposes.

11. Consent Records

The Company maintains records demonstrating user consent and authorization where required. Such records may include clickwrap acceptances, affirmative consent checkboxes, password re-authentication events, enrollment modifications, sharing elections, timestamps, and associated audit records. Consent preferences may be modified or withdrawn by the user through available account settings.

12. Children's Privacy

The Services are not directed toward individuals under eighteen (18) years of age. The Company does not knowingly collect personal information from minors. If the Company becomes aware that information relating to a minor has been collected inadvertently, reasonable measures shall be undertaken to delete such information promptly.

13. Amendments to this Policy

The Company reserves the right to amend, modify, or update this Policy from time to time. Any revised version shall become effective upon posting unless otherwise stated. Continued access to or use of the Services following the effective date of a revised Policy shall constitute acknowledgment of, and agreement to, the revised terms.

14. Contact Information

Questions, requests, complaints, or notices relating to privacy matters should be directed to:

SafeME
Cay Sal Holdings LLC
Email: support@safemeapp.com

The Company has not designated a Data Protection Officer. Responsibility for privacy compliance and oversight rests with the principal of Cay Sal Holdings LLC, who serves as the Company's designated privacy compliance representative.

← Back